Reachable assertion in libheif - #VU135831

 

Reachable assertion in libheif - #VU135831

Published: June 29, 2026


Vulnerability identifier: #VU135831
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to reachable assertion in HeifContext::get_track() when processing a crafted HEIF sequence file that is accepted with no registered sequence tracks. A remote attacker can trick the victim into opening a crafted file to cause a denial of service.

User interaction is required to open or process the crafted HEIF file. In builds with assertions disabled, the issue may instead lead to undefined behavior due to dereferencing an empty track map.


Affected software

libheif

Remediation

Install security update from vendor's website.

libheif - update to 1.23.1

External References

Related Security Bulletins